{"id":"CVE-2024-26306","details":"iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in \"Everlasting ROBOT: the Marvin Attack\" by Hubert Kario.","modified":"2026-08-12T03:30:29.577065555Z","published":"2024-05-13T00:00:00Z","related":["ALSA-2024:4241","ALSA-2024:9185","SUSE-SU-2024:1981-1","openSUSE-SU-2024:13964-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"3.2.0"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26306.json"},"references":[{"type":"WEB","url":"https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc"},{"type":"WEB","url":"https://github.com/esnet/iperf/releases/tag/3.17"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00027.html"},{"type":"WEB","url":"https://www.insyde.com/security-pledge/SA-2024005"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26306.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26306"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250228-0007/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/esnet/iperf","events":[{"introduced":"6f6716aed146d5e2293f94b2ac44f6189f2ccd27"},{"fixed":"64b324df266ae7d44d5a75956b8ff7cbcd1d21fe"}],"database_specific":{"cpe":"cpe:2.3:a:es:iperf3:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"iPerf3"},{"fixed":"3.17"},{"introduced":"0"}],"source":["DESCRIPTION","CPE_RANGE","REFERENCES"]}}],"versions":["3.16","3.16-beta1","3.15","3.14","3.13","3.12","3.11","3.10.1","3.10","3.9","3.8.1","3.8","3.7","3.6","3.5","3.4","3.3","3.2","3.2rc1","3.1","3.1b3","3.1b2","3.1b1","3.0.4","3.0.1","3.0-BETA5","3.0-BETA4","3.0-BETA3","3.0-BETA2","3.0-BETA1","iperf3","3.0-ALPHA1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26306.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}